Google's Quantum AI team published a paper in March 2026 — co-authored with the Ethereum Foundation's Justin Drake and Stanford's Dan Boneh — showing that the elliptic curve cryptography protecting Bitcoin and Ethereum could be broken with fewer than 500,000 physical qubits, a roughly 20-fold red...
"I don't like it either. But I wrote it because I dislike the alternative even more." — Jameson Lopp, Casa CTO and BIP-361 co-author, on proposing to freeze quantum-vulnerable Bitcoin wallets
Google's Quantum AI team published a paper in March 2026 — co-authored with the Ethereum Foundation's Justin Drake and Stanford's Dan Boneh — showing that the elliptic curve cryptography protecting Bitcoin and Ethereum could be broken with fewer than 500,000 physical qubits, a roughly 20-fold reduction from the prior estimate of 9 million qubits. The two largest blockchain networks are now responding with fundamentally different strategies. Bitcoin's BIP-361, drafted by Jameson Lopp and five co-authors, proposes freezing coins in quantum-vulnerable wallets that fail to migrate within a multi-year window. Ethereum's "Lean Ethereum" roadmap, announced by Vitalik Buterin on July 4, 2026, embeds post-quantum cryptography into a seven-fork protocol overhaul targeting completion by 2029.
The divergence is structural, not just technical. Bitcoin's minimalist governance makes coordinated upgrades slow and contentious; Ethereum's foundation-led model allows faster but more centralized response. The data suggests both networks face material risk — Glassnode estimates 6.04 million BTC ($469 billion) already have exposed public keys on-chain — but only one has a funded, staffed, and publicly tracked migration plan.
The paper that shifted the timeline was "Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations," published by Google Quantum AI in March 2026. The key finding: two optimized quantum circuits for solving the 256-bit Elliptic Curve Discrete Logarithm Problem (ECDLP-256) on the secp256k1 curve — the cryptographic backbone of both Bitcoin and Ethereum transaction signatures — require approximately 1,200 to 1,450 logical qubits, translating to fewer than 500,000 physical qubits on a superconducting architecture. The previous best estimate, from Litinski in 2023, required roughly 9 million physical qubits on a photonic architecture.
The paper also modeled a real-time transaction hijacking attack against Bitcoin, yielding a 41% success rate within the 10-minute block confirmation window. According to The Quantum Insider, three separate papers published between January and March 2026 independently compressed the resource estimates for breaking elliptic curve cryptography, creating what researchers now call an accelerated "Q-Day" timeline.
Justin Drake, co-author of the Google paper and Ethereum Foundation researcher, placed 50% odds on Q-Day — the moment a quantum computer recovers a private key from an exposed public key on a live blockchain — arriving by 2032, with a 10% probability as early as 2030. No working quantum computer can perform this attack today. Current hardware tops out below 1,200 physical qubits.
Glassnode's May 2026 analysis quantified the exposure. Of Bitcoin's 20 million issued coins, 6.04 million BTC (30.2% of supply) have public keys visible on-chain, worth approximately $469 billion at the time of analysis. The breakdown:
| Exposure Type | BTC Amount | Description | |---|---|---| | Structural (P2PK) | 1.92 million | Legacy pay-to-public-key outputs from 2009-2012 | | Operational (address reuse) | 4.12 million | Modern wallets that reused addresses, exposing keys | | Exchange-held (subset of operational) | 1.66 million | ~40% of operationally exposed BTC sits on exchanges | | Protected | 13.99 million | 69.8% of supply shows no public-key exposure |
Approximately 1.1 million BTC attributed to Satoshi Nakamoto fall within the structural exposure category. These coins were mined through P2PK outputs and have no seed phrase, parent key, or hardened derivation path — making them unrecoverable under any proposed migration scheme.
Ethereum faces the same underlying cryptographic vulnerability — it uses the same secp256k1 curve. However, the Ethereum Foundation has not published an equivalent on-chain exposure audit. Ethereum's account model differs from Bitcoin's UTXO model; every Ethereum transaction reveals the sender's public key, meaning any account that has sent a transaction has an exposed key. The total exposure is therefore likely proportionally larger than Bitcoin's.
BIP-361, "Post Quantum Migration and Legacy Signature Sunset," was submitted to the bitcoin/bips repository on April 14, 2026 by Lopp and five co-authors. It remains a draft with no activation parameters or signaling mechanism defined. The proposal outlines three phases:
Phase A (~3 years post-activation): Prohibits new transactions from sending funds to legacy address types. Existing holders can still move funds out of vulnerable addresses. The goal is to push wallets and services toward quantum-resistant formats.
Phase B (~5 years post-activation): Invalidates all legacy signatures at the consensus level. Any Bitcoin not yet migrated to quantum-resistant address types becomes frozen — unspendable under network rules.
Phase C (timeline undefined): Establishes a recovery mechanism using zero-knowledge proofs tied to BIP-39 seed phrases, allowing holders who missed the Phase B deadline to reclaim frozen funds by proving ownership without exposing private keys.
The proposal drew immediate backlash. Critics described it as "authoritarian confiscation" and a philosophical departure from Bitcoin's immutability principles. The core tension: protecting the network's economic value requires potentially restricting property rights of holders who fail to act.
As of July 2026, BIP-361 has no champion among Bitcoin Core maintainers. No activation timeline has been proposed. The proposal exists as a conversation starter, not a deployment plan.
Vitalik Buterin announced the "Lean Ethereum" initiative on July 4, 2026, positioning it as the third major iteration of the network — comparable in scope to The Merge in 2022. The plan spans three to four years and covers three priorities: quantum resistance, privacy, and scalability.
The technical roadmap, called the "Strawmap," outlines seven incremental hard forks:
The Ethereum Foundation established a dedicated Post-Quantum Security team in January 2026, led by Thomas Coratger. The team's work is publicly tracked at pq.ethereum.org. Funding includes $2 million in targeted research prizes. A biweekly breakout call on post-quantum transactions operates within the All Core Developers process. Multiple independent teams are running post-quantum consensus test networks.
The Foundation also developed leanVM, a minimalist zero-knowledge proof virtual machine optimized for quantum-resistant hash-based signatures, described as the "cornerstone" of the post-quantum strategy. Native STARK verification is projected to reduce computational costs of decentralized applications by more than 10x.
Full implementation of post-quantum cryptographic signatures across the protocol is targeted for 2029.
The contrast in organizational response is stark.
| Dimension | Bitcoin | Ethereum | |---|---|---| | Lead proposal | BIP-361 (draft, April 2026) | Lean Ethereum Strawmap (July 2026) | | Dedicated team | None | PQ Security team (January 2026) | | Funding | None allocated | $2M research prizes + foundation budget | | Public tracking | GitHub BIP repository only | pq.ethereum.org, biweekly ACD calls | | Test networks | None | Multiple PQ consensus testnets active | | Target completion | No timeline | 2029 | | Governance model | BIP process, miner/node signaling | EF-coordinated, ACD consensus |
Bitcoin's anti-centralization culture — its core philosophical asset — becomes a liability when coordinated action is required on a deadline. BIP-360 (a prerequisite addressing quantum-resistant address formats) has been merged, but BIP-361's freezing mechanism touches Bitcoin's most sacred property: the unconditional right to spend coins you hold keys for.
Ethereum's Foundation-led model enables faster response but introduces centralization risk. The EF can fund teams, set deadlines, and coordinate client developers. Critics argue this makes Ethereum's security posture dependent on a single organization's priorities and execution.
Both ecosystems are developing recovery paths for coins that may be frozen or compromised.
Bitcoin — Project Eleven: On July 15, 2026, post-quantum cryptography firm Project Eleven announced a zero-knowledge proof prototype that runs in 243 milliseconds on a standard laptop. The scheme exploits the fact that quantum computers can break elliptic curve signatures but cannot reverse the one-way hashing used in BIP-39 key derivation. Holders with seed phrases can prove ownership without exposing private keys. According to CoinDesk's July 19, 2026 report, the tool cannot recover Satoshi's ~1.1 million BTC, which were generated without seed phrases or hierarchical derivation paths.
Ethereum — leanVM: The Ethereum Foundation's leanVM provides a protocol-native path. Through EIP-8141 account abstraction in Glamsterdam, individual accounts can opt into quantum-safe signature schemes before any network-wide mandate. This bottom-up migration contrasts with BIP-361's top-down freeze approach.
The quantum threat to blockchain cryptography has moved from theoretical to measurable. Google's paper provided the numbers; Glassnode provided the exposure map. The question is no longer whether to prepare but how fast and at what governance cost.
Ethereum has committed resources, personnel, and a public timeline. Bitcoin has a draft proposal and a community debate. The gap is not primarily technical — both networks use the same vulnerable curve — but organizational. Bitcoin's decentralized governance, designed to resist capture, also resists urgency. Ethereum's foundation model, designed for coordination, also concentrates decision-making.
Neither approach is without cost. Bitcoin risks arriving late to a deadline that, by definition, cannot be extended. Ethereum risks building a migration path that depends on a single organization's continued competence and funding. The market has not yet priced either scenario.